Tobias Brunner
6086029056
libtls: Fix build with DEBUG_LEVEL < 3
2023-05-08 17:32:17 +02:00
Tobias Brunner
19ef2aec15
Update copyright headers after acquisition by secunet
2022-06-28 10:22:56 +02:00
Tobias Brunner
e02f19e3c6
tls-peer: Support answering KeyUpdate requests
2021-02-12 11:45:44 +01:00
Tobias Brunner
ba3c90ded1
libtls: Some code style fixes
2021-02-12 11:45:44 +01:00
bytinbit and ryru
7a2b02667c
libtls: Implement TLS 1.3 handshake on client-side
...
The code is a minimal handshake with the HelloRetryRequest message
implementation missing.
Can be tested with an OpenSSL server running TLS 1.3. The server must
be at least version 1.1.1 (September 2018).
Co-authored-by: ryru <[email protected] >
2021-02-12 11:45:44 +01:00
Tobias Brunner
1003cf2330
Fixed some typos, courtesy of codespell
2017-03-23 18:29:18 +01:00
Andreas Steffen
b12c53ce77
Use standard unsigned integer types
2016-03-24 18:52:48 +01:00
Martin Willi
970378c557
libtls: Don't send TLS close notifies in EAP after application succeeds
...
With the introduction of PT-TLS, we started sending TLS close notifies after
the application layer completes (7bbf7aa9 ). While this makes sense for TCP based
transports, it is not required in EAP methods. In EAP, handshake completion
can be directly signaled using the outer EAP-SUCCESS message. This also saves
one round-trip in the EAP exchange.
Windows 7/8 does not seem to like TLS close notifies at all in EAP, and either
stalls (EAP-TTLS) or disconnects (PEAP).
Fixes #556 .
2015-02-19 11:29:07 +01:00
Martin Willi
7bbf7aa97a
Send TLS close notify if application returns SUCCESS
2013-01-15 17:43:05 +01:00
Tobias Brunner
f05b427265
Moved debug.[ch] to utils folder
2012-10-24 16:00:51 +02:00
Martin Willi
02cabd0f26
Check if TLS handshake received Finished before processing application data
2012-08-09 12:10:41 +02:00
Andreas Steffen
c36680962c
allow to transmit 64k TLS Handshake and Application messages via EAP-[T]TLS
2012-07-11 17:09:04 +02:00
Martin Willi
703c0db894
Check for cipherspec changes after each handshake message
2011-12-31 13:14:49 +01:00
Martin Willi
4caa380625
Separated cipherspec checking and switching, allowing us to defer the second
2011-12-31 13:14:49 +01:00
Tobias Brunner
f3bb1bd039
Fixed common misspellings.
...
Mostly found by 'codespell'.
2011-07-20 16:14:10 +02:00
Andreas Steffen
7e432eff6b
renamed tls_reader|writer to bio_* and moved to libstrongswan
2011-05-31 15:46:51 +02:00
Andreas Steffen
deed58393d
raw TLS debug output
2011-05-29 10:36:41 +02:00
Martin Willi
89821331e0
Do not change cipherspec while we have buffered handshake fragments pending
2010-09-09 14:27:41 +02:00
Martin Willi
ccb65463e7
Check for queued TLS alerts after each handshake part
2010-09-03 09:33:15 +02:00
Andreas Steffen
c3024a0848
fixed typo
2010-08-31 21:42:14 +02:00
Martin Willi
93709d1093
Do not process any more TLS handshake messages on fatal alerts
2010-08-31 18:10:24 +02:00
Martin Willi
d169aab35e
Log TLS handshake subtypes as handshakes
2010-08-31 15:35:29 +02:00
Martin Willi
a596006e3f
Send TLS alerts for errors in TLS handshake building
2010-08-25 18:24:27 +02:00
Martin Willi
ee88ddd6aa
Refactored fragment building, use correct TLS content type for non-first fragments
2010-08-25 18:04:59 +02:00
Martin Willi
a2c1235969
Skip the close notify if application layer completes successfully
2010-08-24 10:30:24 +02:00
Martin Willi
c5142f110e
Check if the application layer has completed successfully
2010-08-24 08:45:49 +02:00
Martin Willi
e6f3ef1330
Implemented TLS Alert handling
2010-08-23 15:13:37 +02:00
Martin Willi
3c19b3461f
Introducing a dedicated debug message group for libtls
2010-08-23 09:47:03 +02:00
Andreas Steffen
fd86fb5183
removed debug output for TLS application data
2010-08-19 07:27:30 +02:00
Andreas Steffen
ee346b54c1
add TLS handshake packet size to debug output
2010-08-18 22:07:27 +02:00
Andreas Steffen
c4347aa86e
do not dump tls application data any more
2010-08-13 21:21:49 +02:00
Andreas Steffen
3a15a02a58
set TLS record type before state change to STATE_FINISHED_SENT
2010-08-13 00:31:45 +02:00
Andreas Steffen
1327839da8
added generic TLS application data handler and specific EAP-TTLS instantiation
2010-08-12 23:58:54 +02:00
Andreas Steffen
289c9ac3d7
log TLS handshake messages in debug level 2
2010-08-04 16:55:55 +02:00
Martin Willi
0f82a47063
Moved TLS stack to its own library
2010-08-03 15:39:26 +02:00